Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

19 billion stolen passwords: are your IAM controls still fit for purpose?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19663
Topic starter  

TL;DR: Cybernews reported 19,030,305,929 passwords on the dark web, the largest stolen credential stockpile ever found, with most attributed to InfoStealer malware and social engineering, according to Unixi. The finding shows that password-dependent IAM collapses once credentials are exposed, because reuse, short length, and weak complexity make takeover and brute force attacks easier.

NHIMG editorial — based on content published by Unixi: 19 billion passwords on the dark web and the case for passwordless access

By the numbers:

Questions worth separating out

Q: What breaks when users reuse passwords across multiple services?

A: One exposed credential can become many compromised accounts.

Q: Why do stolen password dumps create such a large identity risk?

A: Stolen password dumps create risk because attackers can automate attempts at scale, test reused credentials across services, and target high-value accounts with little friction.

Q: How can organisations tell whether password governance is working?

A: They should measure ticket reduction, reset completion time, audit trail quality, and whether emergency recovery works across all connected identity systems.

Practitioner guidance

  • Measure password reuse across the identity estate Inventory reused credentials, short passwords, and accounts that still rely on shared secrets.
  • Accelerate phishing-resistant authentication adoption Move high-risk user populations toward passwordless or phishing-resistant factors for primary access and recovery flows.
  • Harden endpoint exposure to credential theft Treat smishing and InfoStealer-style malware as identity threats, not just malware alerts.

What's in the full article

Unixi's full article covers the passwordless product angle and implementation context this post intentionally leaves for the source:

  • How Unixi frames Universal SSO as a passwordless login approach for multiple systems
  • The product-specific onboarding flow and user experience details behind its passwordless access model
  • The vendor's explanation of how its approach fits into a broader move away from passwords
  • The call-to-action and implementation context that sit outside this independent identity analysis

👉 Read Unixi's analysis of 19 billion stolen passwords and passwordless IAM →

19 billion stolen passwords: are your IAM controls still fit for purpose?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19254
 

Passwords fail as a governance control once attackers can industrialise credential reuse. The article is not really about one breach dump. It is about the collapse of a control model that assumes human secrecy, individual memorisation, and low reuse will hold under adversarial pressure. In identity governance terms, password policy becomes a weak proxy for assurance when the real issue is how easily a stolen secret can be replayed across services. The practitioner conclusion is straightforward: password strength alone does not equal identity assurance.

A few things that frame the scale:

  • Only 6% of organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
  • Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, with inadequate monitoring and logging and over-privileged accounts both cited by 37%.

A question worth separating out:

Q: Should organisations move away from passwords for high-risk access?

A: Yes, especially for privileged, remote, and frequently targeted accounts. Passwordless or phishing-resistant authentication reduces the reuse value of stolen credentials and makes bulk password dumps less useful to attackers. Organisations should phase the change in where account takeover would cause the most damage.

👉 Read our full editorial: 19 billion stolen passwords expose the case for passwordless IAM



   
ReplyQuote
Share: